]> git.ipfire.org Git - ipfire-2.x.git/log
ipfire-2.x.git
5 weeks agoinitscripts: update riscv64 rootfile
Arne Fitzenreiter [Mon, 8 Apr 2024 08:14:17 +0000 (10:14 +0200)] 
initscripts: update riscv64 rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agokernel: update riscv64 config and rootfile
Arne Fitzenreiter [Mon, 8 Apr 2024 08:10:27 +0000 (10:10 +0200)] 
kernel: update riscv64 config and rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agokernel: enable CPUFREQ for Raspberry Pi
Arne Fitzenreiter [Sat, 6 Apr 2024 07:43:01 +0000 (07:43 +0000)] 
kernel: enable CPUFREQ for Raspberry Pi

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinitskripts: update aarch64 rootfile
Arne Fitzenreiter [Sat, 6 Apr 2024 07:42:21 +0000 (07:42 +0000)] 
initskripts: update aarch64 rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Fri, 5 Apr 2024 20:29:37 +0000 (22:29 +0200)] 
Merge remote-tracking branch 'origin/master' into next

5 weeks agokernel: update to 6.6.25
Arne Fitzenreiter [Fri, 5 Apr 2024 20:27:55 +0000 (22:27 +0200)] 
kernel: update to 6.6.25

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agosuricata: Disable fail-open on NFQUEUE
Michael Tremer [Wed, 3 Apr 2024 20:42:13 +0000 (21:42 +0100)] 
suricata: Disable fail-open on NFQUEUE

This change causes that if suricata crashes, the NFQUEUE will no longer
fall into a mode where ALL packets are being accepted. This used the be
the case before which opened the entire firewall.

If suricata randomly crashes, we will fall back to the "bypass" mode
where packets will bypass suricata, but nothing else.

Fixes: #13642
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agokernel: update to 6.6.24
Arne Fitzenreiter [Thu, 4 Apr 2024 21:33:01 +0000 (23:33 +0200)] 
kernel: update to 6.6.24

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agocore186: add collectd to updater
Arne Fitzenreiter [Thu, 4 Apr 2024 16:26:55 +0000 (18:26 +0200)] 
core186: add collectd to updater

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agocollectd: fix cpufreq graph if virtual cores are offline
Arne Fitzenreiter [Thu, 4 Apr 2024 16:23:29 +0000 (18:23 +0200)] 
collectd: fix cpufreq graph if virtual cores are offline

the kernel doesn't allow to read the frequency of a offline virtual core
if smt is disabled so now no error is reported in this case and NaN submited to the
database.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agocore186: add grub-btrfs initskript changes to updater
Arne Fitzenreiter [Tue, 2 Apr 2024 19:36:46 +0000 (19:36 +0000)] 
core186: add grub-btrfs initskript changes to updater

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agogrub-btrfsd: Drop redundant used PIDFILE mechanism
Stefan Schantl [Wed, 27 Mar 2024 19:39:20 +0000 (20:39 +0100)] 
grub-btrfsd: Drop redundant used PIDFILE mechanism

This case is already covered by the PID mechanism of the used functions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agogrub-btrfsd: Adjust displayed starting message
Stefan Schantl [Wed, 27 Mar 2024 19:39:19 +0000 (20:39 +0100)] 
grub-btrfsd: Adjust displayed starting message

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agogrub-btrfsd: Use generic volume_fs_type function for FS detection
Stefan Schantl [Wed, 27 Mar 2024 19:39:18 +0000 (20:39 +0100)] 
grub-btrfsd: Use generic volume_fs_type function for FS detection

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agoinitscripts: Add generic function to get the filesystem type of a volume
Stefan Schantl [Wed, 27 Mar 2024 19:39:17 +0000 (20:39 +0100)] 
initscripts: Add generic function to get the filesystem type of a volume

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agogrub-btrfs: fix grub-btrfs build and remove bugtracker url
Arne Fitzenreiter [Sun, 31 Mar 2024 14:30:50 +0000 (16:30 +0200)] 
grub-btrfs: fix grub-btrfs build and remove bugtracker url

grub-btrfs try to reconfigure grub in the buildsystem and print always the bugtracker url on every error even when its not a bug

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Sun, 31 Mar 2024 11:36:08 +0000 (13:36 +0200)] 
Merge remote-tracking branch 'origin/master' into next

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agocore185: excplicit erase liblzma.so.5.6.*
Arne Fitzenreiter [Sun, 31 Mar 2024 11:27:46 +0000 (13:27 +0200)] 
core185: excplicit erase liblzma.so.5.6.*

because if this file exist the cleanap script will remove the older version after downgrade
and the system still use the malewared version.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agokernel: update to 6.6.23
Arne Fitzenreiter [Sun, 31 Mar 2024 08:49:46 +0000 (10:49 +0200)] 
kernel: update to 6.6.23

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agofrr: Bump release version
Michael Tremer [Sat, 30 Mar 2024 12:14:51 +0000 (12:14 +0000)] 
frr: Bump release version

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agofrr: Update reloading all services
Michael Tremer [Thu, 28 Mar 2024 17:41:12 +0000 (17:41 +0000)] 
frr: Update reloading all services

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agofrr: Start the management daemon, too
Michael Tremer [Thu, 28 Mar 2024 17:41:11 +0000 (17:41 +0000)] 
frr: Start the management daemon, too

This daemon is running the configuration validation and required to run
at all times.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoprotobuf-c: Ship libraries
Michael Tremer [Thu, 28 Mar 2024 17:41:10 +0000 (17:41 +0000)] 
protobuf-c: Ship libraries

FRR links against this and fails to start without.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agomake.sh: Update contributors
Michael Tremer [Sat, 30 Mar 2024 12:13:08 +0000 (12:13 +0000)] 
make.sh: Update contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoREADME.md: fix minor typo
Rico Hoppe [Thu, 28 Mar 2024 09:51:53 +0000 (09:51 +0000)] 
README.md: fix minor typo

Signed-off-by: Rico Hoppe <rico.hoppe@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoREADME.md: update text & adjust links to new URLs
Rico Hoppe [Thu, 28 Mar 2024 09:51:52 +0000 (09:51 +0000)] 
README.md: update text & adjust links to new URLs

- links for: about, documentation, help
- wording: wiki to documentation

Signed-off-by: Rico Hoppe <rico.hoppe@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agocore185: Ship new perl modules for libarchive
Michael Tremer [Sat, 30 Mar 2024 12:11:42 +0000 (12:11 +0000)] 
core185: Ship new perl modules for libarchive

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoids-functions.pl: Use libarchive to extract archives
Stefan Schantl [Sat, 30 Mar 2024 11:35:30 +0000 (12:35 +0100)] 
ids-functions.pl: Use libarchive to extract archives

This gives us a lot of benefits:

* Speed up the extraction process
* More supported archive types due the power of libarchive
* Support of passphrase protected archives

It also fixes a problem with non extracted files next to a zero sized
file inside an archive.

Fixes #13632.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoperl-Archive-Peek-Libarchive: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:29 +0000 (12:35 +0100)] 
perl-Archive-Peek-Libarchive: New package

As very simple XS based perl binding for libarchive
to get header data and extract files.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoperl-Object-Tiny: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:28 +0000 (12:35 +0100)] 
perl-Object-Tiny: New package

This is a runtime dependency of perl-Archive-Peek-Libarchive

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoperl-Config-AutoConf: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:27 +0000 (12:35 +0100)] 
perl-Config-AutoConf: New package

This is only a build dependency for perl-Arhive-Peek-Libarchive and
will not be installed on a system

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoperl-Capture-Tiny: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:26 +0000 (12:35 +0100)] 
perl-Capture-Tiny: New package

This is only a build dependency for perl-Config-AutoConf and
will not be installed on a system

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agocore185: Ship everything that is linked against XZ
Michael Tremer [Sat, 30 Mar 2024 12:07:22 +0000 (12:07 +0000)] 
core185: Ship everything that is linked against XZ

This is a precautionary step to avoid that we have any issues to face
because of a downgrade as new symbols have been added to liblzma 5.6.0.

Furthermore, this should avoid shipping any traces of any other
potential malware in XZ that has been added in 5.6.0 or after.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoxz: Remove excess whitespace
Michael Tremer [Sat, 30 Mar 2024 11:58:24 +0000 (11:58 +0000)] 
xz: Remove excess whitespace

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoxz: Revert back to version 5.4.5 due to backdoor issue
Adolf Belka [Sat, 30 Mar 2024 08:14:58 +0000 (09:14 +0100)] 
xz: Revert back to version 5.4.5 due to backdoor issue

- xz version 5.6.0 and 5.6.1 discovered to have been backdoored by what looks to have
   been one of the xz devs.
- IPFire looks not to be affected by the problem as we don't patch openssh to be linked
   with liblzma
- However due to question marks about what else might be in these 5.6.x versions it is
   better to revert back to a version that did not have the build-to-host.m4 file with the
   code that modifies the build if it meets certain criteria.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Wed, 27 Mar 2024 17:27:30 +0000 (18:27 +0100)] 
Merge remote-tracking branch 'origin/master' into next

7 weeks agogrub-btrfs: remove boot/grub/grubenv
Arne Fitzenreiter [Wed, 27 Mar 2024 01:59:07 +0000 (02:59 +0100)] 
grub-btrfs: remove boot/grub/grubenv

this file should created by grub-install at installation.
Also it is not present on aarch64 builds of grub.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoIPS: Fix how we show EOL providers
Michael Tremer [Tue, 26 Mar 2024 15:08:01 +0000 (15:08 +0000)] 
IPS: Fix how we show EOL providers

There is no need to add a legend as I find it confusing. The change that
people are using an EOL is rather slim and so I don't to waste space.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 weeks agocore185: Fix update.sh syntax issues
Michael Tremer [Tue, 26 Mar 2024 14:43:39 +0000 (14:43 +0000)] 
core185: Fix update.sh syntax issues

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 weeks agoCU185-update.sh: Add drop hostile in & out logging entries if not already present
Adolf Belka [Mon, 25 Mar 2024 17:44:56 +0000 (18:44 +0100)] 
CU185-update.sh: Add drop hostile in & out logging entries if not already present

- This v2 patch corrects that the previous script was looking for =on. If a user had
   modified the preferences to change it to =off then the script would have resulted in
   both =on and =off versions being in the settings file.
- This patch ensures that those people who updated to CU184 before the CU184-update.sh
   patch fix to add the logging entries was added will get their optionsfw settings file
   correctly updated with CU185
- This only adds the LOGDROPHOSTILEIN & LOGDROPHOSTILEOUT entries if they do not already
   exist in the optionsfw settings file.
- This change also does the check for LOGDROPHOSTILEIN and LOGDROPHOSTILEOUT as two
   separate checks and then runs the firewall update command

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 weeks agocore186: add brtfs related changes to updater
Arne Fitzenreiter [Tue, 26 Mar 2024 07:40:56 +0000 (07:40 +0000)] 
core186: add brtfs related changes to updater

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agogrub-btrfs: New package
Stefan Schantl [Sun, 24 Mar 2024 12:39:53 +0000 (13:39 +0100)] 
grub-btrfs: New package

This kind of grub addon will extend the grub boot menu by a additional
submenu where a BTRFS snapshot can be selected to directly use as root
volume and boot into it.

The grub-btrfsd daemon is using inotify(tools) to watch the snapshot directory for
new or deleted snapshots and calls grub-mkconfig to adjust the snapshot grub submenu

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinotify-tools: New package
Stefan Schantl [Sun, 24 Mar 2024 12:39:52 +0000 (13:39 +0100)] 
inotify-tools: New package

This package is required for the grub-btrfs daemon

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Pass choosen filesystem to hw_make_destination
Stefan Schantl [Sun, 24 Mar 2024 12:37:35 +0000 (13:37 +0100)] 
installer: Pass choosen filesystem to hw_make_destination

This is required to proper choose if a seperate boot partition should be
created or must not created (BTRFS)

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Add code to correctly write the fstab when installing on BTRFS
Stefan Schantl [Sat, 23 Mar 2024 10:56:29 +0000 (11:56 +0100)] 
installer: Add code to correctly write the fstab when installing on BTRFS

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Add code to proper unmount the BTRFS layout
Stefan Schantl [Sat, 23 Mar 2024 10:56:28 +0000 (11:56 +0100)] 
installer: Add code to proper unmount the BTRFS layout

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Define common mount options for BTRFS volumes
Stefan Schantl [Sat, 23 Mar 2024 10:56:27 +0000 (11:56 +0100)] 
installer: Define common mount options for BTRFS volumes

As default we are using zstd for compression with level 1

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Mount BTRFS layout before installing the system
Stefan Schantl [Sat, 23 Mar 2024 10:56:26 +0000 (11:56 +0100)] 
installer: Mount BTRFS layout before installing the system

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Allow writing to the debug console from anywhere
Stefan Schantl [Sat, 23 Mar 2024 10:56:25 +0000 (11:56 +0100)] 
installer: Allow writing to the debug console from anywhere

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Add recurisve mkdir function
Stefan Schantl [Sat, 23 Mar 2024 10:56:24 +0000 (11:56 +0100)] 
installer: Add recurisve mkdir function

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Add code to create a BTRFS subvolume layout
Stefan Schantl [Sat, 23 Mar 2024 10:56:23 +0000 (11:56 +0100)] 
installer: Add code to create a BTRFS subvolume layout

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Disable own boot partition when using BTRFS
Stefan Schantl [Sat, 23 Mar 2024 10:56:22 +0000 (11:56 +0100)] 
installer: Disable own boot partition when using BTRFS

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Ensure to always create the /boot directory.
Stefan Schantl [Sat, 23 Mar 2024 10:56:21 +0000 (11:56 +0100)] 
installer: Ensure to always create the /boot directory.

Ensure to always create the /boot directory during the mounting
of the various created file systems. If the /boot directory does not
exist some following mount operations could not be performed correctly
and the installation/mounting will fail.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agodracut: Ship BTRFS related modules
Stefan Schantl [Sat, 23 Mar 2024 10:56:20 +0000 (11:56 +0100)] 
dracut: Ship BTRFS related modules

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoinstaller: Allow to install IPFire on BTRFS
Stefan Schantl [Sat, 23 Mar 2024 10:56:19 +0000 (11:56 +0100)] 
installer: Allow to install IPFire on BTRFS

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agobtrfs-progs: New package
Stefan Schantl [Sat, 23 Mar 2024 10:56:18 +0000 (11:56 +0100)] 
btrfs-progs: New package

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Tue, 26 Mar 2024 07:28:20 +0000 (07:28 +0000)] 
Merge remote-tracking branch 'origin/master' into next

7 weeks agoshadow: Update login.defs to remove reference to cracklib
Adolf Belka [Mon, 25 Mar 2024 13:41:38 +0000 (14:41 +0100)] 
shadow: Update login.defs to remove reference to cracklib

- From shadow-15.0.0 all references to cracklib were removed from shadow. Apparently
   some functions were no longer accessible and the shadow team decided to remove cracklib
   references completely. This was not mentioned in the changelkog for 15.0.0
- This resulkts in gettinbg the message configuration error - unknown item
   'CRACKKLIB_DICTPATH' ( notify administrator ) when logging in to the console.
- The login to the console occurs successfully so the message is only a warning that
   cracklib is no longer used.
- IPfire does not use cracklkib anyway so this patch removes the section referring to
   cracklib from the login.defs configuration file.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 weeks agosamba: Add wsdd as a dependency to samba
Adolf Belka [Mon, 25 Mar 2024 11:17:52 +0000 (12:17 +0100)] 
samba: Add wsdd as a dependency to samba

- Add wsdd as a dependency to samba so it will be installed together with samba

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Sun, 24 Mar 2024 07:48:51 +0000 (08:48 +0100)] 
Merge remote-tracking branch 'origin/master' into next

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
8 weeks agoCU185-update.sh: Add drop hostile in & out logging entries if not already present
Adolf Belka [Wed, 20 Mar 2024 14:43:27 +0000 (15:43 +0100)] 
CU185-update.sh: Add drop hostile in & out logging entries if not already present

- This patch ensures that those people who updated to CU184 before the CU184-update.sh
   patch fix to add the logging entries was added will get their optionsfw settings file
   correctly updated with CU185
- This only adds the LOGDROPHOSTILEIN & LOGDROPHOSTILEOUT entries if they do noit already
   exist in the optionsfw settings file.

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agoids.cgi: Improve add provider logic
Stefan Schantl [Fri, 22 Mar 2024 05:01:45 +0000 (06:01 +0100)] 
ids.cgi: Improve add provider logic

Do not longer add unsupported/removed providers as an option
when adding a new/first ruleset provider.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agocore185: Ship IPS files
Michael Tremer [Fri, 22 Mar 2024 15:29:22 +0000 (15:29 +0000)] 
core185: Ship IPS files

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agoids.cgi: Adjust code for marking unsupported providers
Stefan Schantl [Thu, 21 Mar 2024 20:51:18 +0000 (21:51 +0100)] 
ids.cgi: Adjust code for marking unsupported providers

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agoruleset-sources: Restore generic details about recently dropped providers
Stefan Schantl [Thu, 21 Mar 2024 20:51:17 +0000 (21:51 +0100)] 
ruleset-sources: Restore generic details about recently dropped providers

At least these informations are required to display something usefull
on the webgui, even if a provider has been dropped.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agoupdate-ids-ruleset: Disable provider if not dl_url can be obtained
Stefan Schantl [Thu, 21 Mar 2024 20:51:16 +0000 (21:51 +0100)] 
update-ids-ruleset: Disable provider if not dl_url can be obtained

Unsupported/Removed provides does not longer have these information

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agoids.cgi: Change check if a provider is not longer supported
Stefan Schantl [Thu, 21 Mar 2024 20:51:15 +0000 (21:51 +0100)] 
ids.cgi: Change check if a provider is not longer supported

This check is now based on a download URL instead of checking if
an entry in the ruleset sources is present.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agoids-functions.pl: Improve logic to get the cached rulesfile of a provider
Stefan Schantl [Thu, 21 Mar 2024 20:51:14 +0000 (21:51 +0100)] 
ids-functions.pl: Improve logic to get the cached rulesfile of a provider

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agokernel: update aarch64 rootfile
Arne Fitzenreiter [Fri, 22 Mar 2024 10:58:49 +0000 (11:58 +0100)] 
kernel: update aarch64 rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
8 weeks agocore186: start update
Arne Fitzenreiter [Fri, 22 Mar 2024 05:39:34 +0000 (06:39 +0100)] 
core186: start update

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
8 weeks agovulnerabilities.cgi: add RFDS (CVE-2ß23-28746) to list
Arne Fitzenreiter [Thu, 21 Mar 2024 18:12:14 +0000 (19:12 +0100)] 
vulnerabilities.cgi: add RFDS (CVE-2ß23-28746) to list

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
8 weeks agokernel: update to 6.6.22
Arne Fitzenreiter [Wed, 20 Mar 2024 16:28:43 +0000 (17:28 +0100)] 
kernel: update to 6.6.22

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
8 weeks agocore185: Ship IPS ruleset sources
Michael Tremer [Thu, 21 Mar 2024 14:56:41 +0000 (14:56 +0000)] 
core185: Ship IPS ruleset sources

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agocpufrequtils: remove cpufrequtils
Arne Fitzenreiter [Wed, 20 Mar 2024 08:28:51 +0000 (09:28 +0100)] 
cpufrequtils: remove cpufrequtils

the only file in the package is now the initskript to configre powersave mode using cpupower
which is shipped with the kernel.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
8 weeks agokernel: build cpupower
Arne Fitzenreiter [Wed, 20 Mar 2024 08:27:50 +0000 (09:27 +0100)] 
kernel: build cpupower

cpupower replace the function of cpufrequtils which is not updated since years.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
8 weeks agosuricata: Update to 7.0.4
Michael Tremer [Wed, 20 Mar 2024 10:03:51 +0000 (10:03 +0000)] 
suricata: Update to 7.0.4

  https://suricata.io/2024/03/19/suricata-7-0-4-and-6-0-17-released/

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agocore185: Ship libhtp
Michael Tremer [Wed, 20 Mar 2024 10:01:13 +0000 (10:01 +0000)] 
core185: Ship libhtp

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agolibhtp: Update to 0.5.47
Michael Tremer [Wed, 20 Mar 2024 10:00:51 +0000 (10:00 +0000)] 
libhtp: Update to 0.5.47

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agoConfig: Update source upload URL
Michael Tremer [Wed, 20 Mar 2024 09:56:14 +0000 (09:56 +0000)] 
Config: Update source upload URL

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agowsdd: Remove dropped initscript
Michael Tremer [Tue, 19 Mar 2024 11:14:42 +0000 (11:14 +0000)] 
wsdd: Remove dropped initscript

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agowsdd: Update install and uninstall pak files
Adolf Belka [Mon, 18 Mar 2024 18:43:14 +0000 (19:43 +0100)] 
wsdd: Update install and uninstall pak files

- As wsdd is now started by samba when it is started then the wsdd install and uninstall
   paks no longer need to create the symlinks for starting and stopping wsdd and no longer
   need the start_service and stop_service commands in the paks.

Fixes: bug#13445
Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agowsdd: Update of lfs file - fixes bug#13445
Adolf Belka [Mon, 18 Mar 2024 18:43:13 +0000 (19:43 +0100)] 
wsdd: Update of lfs file - fixes bug#13445

- Removal of services line as wsdd will now be started by the samba option in the addon
   services wui page
- Removal of installing separate wsdd initscript as it is nowe integrated into the samba
   initscript.

Fixes: bug#13445
Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agowsdd: remove wsdd initscript as now covered by samba - fixes bug#13445
Adolf Belka [Mon, 18 Mar 2024 18:43:12 +0000 (19:43 +0100)] 
wsdd: remove wsdd initscript as now covered by samba - fixes bug#13445

Fixes: bug#13445
Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agosamba: Integrate wsdd initscript into samba initscript - bug#13445
Adolf Belka [Mon, 18 Mar 2024 18:43:11 +0000 (19:43 +0100)] 
samba: Integrate wsdd initscript into samba initscript - bug#13445

- This integrates the wsdd initscript functions into the samba initscript. When samba is
   started or stopped or the status requested then wsdd is part of that process.
- Tested in my vm testbed and confirmed to work for start, stop and status. Confirmed
   pid's shown with status command are in the appropriate pid files.

Fixes: bug#13445
Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agocore185: Ship ppp
Michael Tremer [Tue, 19 Mar 2024 11:10:19 +0000 (11:10 +0000)] 
core185: Ship ppp

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agoppp: Update to include bug fixes that should be in 2.5.1 but not yet released
Adolf Belka [Fri, 15 Mar 2024 12:38:06 +0000 (13:38 +0100)] 
ppp: Update to include bug fixes that should be in 2.5.1 but not yet released

- Update from version 2.5.0 to commit e1266c7
- Update of rootfile
- When ppp-2.5.0 was released it had a bug bin it that the lock and run directories
   had non standard defaults but also that if the directory did not exist ppp just
   ignored it and continued to start but would then have error messages in the logs about
   not being able to cretae the lock file
- This issue was raised in the ppp github issues and a set of patches merged into ppp.
- The plan was written in Nov 2023 that this would be released as 2.5.1, however nearly
   three months later there is no sight of 2.5.1 being released and people continue to
   flag up the lock directory issues and have to apply a workaround to create the directory
   in local.rc
- This patch has taken the zip source tarball of master at the commit e1266c7. The zip
   tarball was then extracted and then tar'd back up as a tar.gz file with the version set
   at e1266c7 rather than master. I could not find any other way to get a source tarball\
   created at a certain commit stage.
- The patch ppp-2.5.0-2-everywhere-O_CLOEXEC-harder.patch had to be updated due to some
   changes in the source files.
- The patch ppp-2.5.0-7-add-configure-check-to-see-if-we-have-struct-sockaddr_ll.patch
   was removed as the changes are now built into the source tarball.
- This will need to be tested thoroughly by people with ppp to confirm that the lock
   directory is created if it doesn't exist on the system. I can't test that as I have
   no access to a ppp connection system.
- For a view of the changelog between 2.5.0 and e1266c7 the github commits list needs to
   be reviewed. https://github.com/ppp-project/ppp/commits/master/?before=e1266c76d1ad39f98f11676e34f180f78c5a510c+35

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agomake.sh: Update contributors
Michael Tremer [Mon, 18 Mar 2024 16:17:53 +0000 (16:17 +0000)] 
make.sh: Update contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agounbound: Update to 1.19.3
Matthias Fischer [Sat, 16 Mar 2024 15:31:43 +0000 (16:31 +0100)] 
unbound: Update to 1.19.3

For details see:
https://nlnetlabs.nl/projects/unbound/download/#unbound-1-19-3

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
8 weeks agoMerge branch 'master' into next
Michael Tremer [Mon, 18 Mar 2024 10:14:50 +0000 (10:14 +0000)] 
Merge branch 'master' into next

8 weeks agoCU184-update.sh: Add drop hostile in & out logging entries core184
Adolf Belka [Sat, 16 Mar 2024 09:32:54 +0000 (10:32 +0100)] 
CU184-update.sh: Add drop hostile in & out logging entries

- My drop hostile patch set updated the WUI entries to include in and out logging options
   but the values need to be added to the optionsfw entries for existing systems being
   upgraded.
- After the existing CU184 update the LOGDROPHOSTILEIN and LOGDROPHO)STILEOUT entries
   are not in the settings file which trewats them as being set to off, even though they
   are enabled in the WUI update.
- This patch adds the LOGDROPHOSTILEIN and LOGDROPHOSTILEOUT entries into the settings
   file and then runs the firewallctrl command to apply to the firewall.
- Ran a CU184 update on a CU183 vm system and then ran the comands added into the update.sh
   script and then did a reboot. Entries include and DROP_HOSTILE entries start to be
   logged again.

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 months agomympd: update to 14.1.0
Arne Fitzenreiter [Fri, 15 Mar 2024 11:12:34 +0000 (12:12 +0100)] 
mympd: update to 14.1.0

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 months agotools: Rewrite checkrootfiles
Michael Tremer [Fri, 15 Mar 2024 10:49:12 +0000 (10:49 +0000)] 
tools: Rewrite checkrootfiles

This is a clean rewrite that makes the script a little bit more modular
and easier to use. It should also show clearer error messages.

Finally, it removes the exclusion of various files that are no longer a
hit any more. The only legitimate exception is qemu.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 months agocore185: Ship time.cgi
Michael Tremer [Thu, 14 Mar 2024 19:17:04 +0000 (19:17 +0000)] 
core185: Ship time.cgi

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 months agotime.cgi: Add German translation
Michael Tremer [Thu, 14 Mar 2024 18:49:51 +0000 (18:49 +0000)] 
time.cgi: Add German translation

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 months agotime.cgi: add current date-time to this WebGUI page
Jon Murphy [Mon, 11 Mar 2024 23:45:00 +0000 (18:45 -0500)] 
time.cgi: add current date-time to this WebGUI page

- added words and date-time format to english (en.pl)
- other languages are needed
- seconds included since time is accurate to < .1s
https://git.ipfire.org/?p=ipfire-2.x.git;a=commit;h=2234e8aacac2e0d0b06dac4513585c15c2b3b440

Code-by: Leo-Andres Hofmann <hofmann@leo-andres.de>
Signed-off-by: Jon Murphy <jon.murphy@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 months agoexpat: Update to version 2.6.2
Adolf Belka [Thu, 14 Mar 2024 16:52:08 +0000 (17:52 +0100)] 
expat: Update to version 2.6.2

- Update from version 2.6.1 to 2.6.2
- Update of rootfile
- Changelog
    2.6.2
       Security fixes:
       #839 #842  CVE-2024-28757 -- Prevent billion laughs attacks with
                    isolated use of external parsers.  Please see the commit
                    message of commit 1d50b80cf31de87750103656f6eb693746854aa8
                    for details.
       Bug fixes:
       #839 #841  Reject direct parameter entity recursion
                    and avoid the related undefined behavior
       Other changes:
            #847  Autotools: Fix build for DOCBOOK_TO_MAN containing spaces
            #837  Add missing #821 and #824 to 2.6.1 change log
       #838 #843  Version info bumped from 10:1:9 (libexpat*.so.1.9.1)
                    to 10:2:9 (libexpat*.so.1.9.2); see https://verbump.de/
                    for what these numbers do

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 months agodnsdist: Update to 1.9.1
Michael Tremer [Thu, 14 Mar 2024 14:17:54 +0000 (14:17 +0000)] 
dnsdist: Update to 1.9.1

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 months agoxz: Update to version 5.6.1
Adolf Belka [Thu, 14 Mar 2024 13:32:58 +0000 (14:32 +0100)] 
xz: Update to version 5.6.1

- Update from version 5.6.0 to 5.6.1
- Update of rootfile
- Changelog
    5.6.1
    * liblzma: Fixed two bugs relating to GNU indirect function (IFUNC)
      with GCC. The more serious bug caused a program linked with
      liblzma to crash on start up if the flag -fprofile-generate was
      used to build liblzma. The second bug caused liblzma to falsely
      report an invalid write to Valgrind when loading liblzma.
    * xz: Changed the messages for thread reduction due to memory
      constraints to only appear under the highest verbosity level.
    * Build:
        - Fixed a build issue when the header file <linux/landlock.h>
          was present on the system but the Landlock system calls were
          not defined in <sys/syscall.h>.
        - The CMake build now warns and disables NLS if both gettext
          tools and pre-created .gmo files are missing. Previously,
          this caused the CMake build to fail.
    * Minor improvements to man pages.
    * Minor improvements to tests.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 months agocore185: Ship wget
Michael Tremer [Thu, 14 Mar 2024 14:15:16 +0000 (14:15 +0000)] 
core185: Ship wget

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 months agowget: Update to version 1.24.5
Adolf Belka [Thu, 14 Mar 2024 13:32:57 +0000 (14:32 +0100)] 
wget: Update to version 1.24.5

- Update from version 1.21.4 to 1.24.5
- Update of rootfile not required
- Changelog
    1.24.5
** Fix how subdomain matches are checked for HSTS.
   Fixes a minor issue where cookies may be leaked to the wrong domain
** Wget will now also parse the srcset attribute in <source> HTML tags
** Support reading fetchmail style "user" and "passwd" fields from netrc
** In some cases, prevent the confusing "Cannot write to... (success)" error messages
** Support extremely fast download speeds (TB/s).
   Previously this would cause Wget to crash when printing the speed
** Improve portability on OpenBSD to run the test suite
** Ensure that CSS URLs are corectly quoted (Bug: 64082)

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>